Security
Last updated: July 27, 2026
1. Our Approach
We build and operate systems that touch our clients' operational data, so security is part of how every engagement is scoped, built, and run — not an afterthought. Our practices are informed by SOC 2 and NIST Cybersecurity Framework principles. We are a small senior team, and we would rather show you exactly how your data is handled than hide behind badges: every client is welcome to a security review before or during an engagement.
2. Data Protection
- Data in transit: TLS 1.2 or higher for all communications
- Data at rest: AES-256 encryption via our cloud providers
- Data residency: client data is stored and processed in United States cloud regions by default
- Client data is logically separated per engagement, with separate development, staging, and production environments
3. Access Control
- Least-privilege access: personnel receive only the access an engagement requires
- Multi-factor authentication on administrative and cloud accounts
- Access to production systems and client data is logged
- Access is reviewed per engagement and revoked promptly when no longer needed or at engagement end
4. AI and Model Practices
- Client data is never used to train models shared with other customers
- Where third-party AI model providers are used, we select offerings whose terms do not permit training on submitted data
- Workflows are designed with human review: low-confidence outputs are flagged for people, and external actions require approval
- Development and testing use synthetic or de-identified data where practical
5. Development Practices
- Code review before production changes
- Secrets kept in managed secret stores, never in source code
- Dependency and vulnerability scanning
- Audit trails for system actions in the workflows we build
6. Infrastructure
We build on established cloud providers (such as Cloudflare, AWS, and managed database services) in United States regions by default, and rely on their physical data center security, redundancy, and DDoS protections. Backups are automated and tested as part of each operated engagement.
7. Edge and Hardware Deployments
For on-site vision and hardware systems, processing runs locally where the deployment allows: footage and images stay on-site by default, and only structured results (for example, a trailer number and timestamp) leave the device, over encrypted connections. Site-specific data flows are documented in the engagement's SOW.
8. Personnel and Subcontractors
- All personnel and subcontractors are bound by written confidentiality obligations
- Production and client data access is need-to-know and logged
- Engagement-specific data-handling restrictions, including where data may be accessed from, are honored per the SOW
9. Incident Response
We maintain documented procedures for detecting, containing, and recovering from security incidents. If an incident affects your data, we will notify you without undue delay, consistent with our contract and applicable law, and share findings and remediation steps.
10. Client Security Reviews
Bring your IT team. For any engagement we will walk through architecture and data flows, complete security questionnaires, and document who has access to what. Data-flow diagrams and access lists are available per engagement.
11. Responsible Disclosure
If you discover a security vulnerability, please report it to security@logipilot.ai. We will acknowledge receipt promptly, keep you informed as we investigate, and address confirmed issues responsibly.
12. Contact Information
For security-related questions, contact us at:
LogiPilot, Inc.
Email: security@logipilot.ai or hello@logipilot.ai